← Zurück zur CVE-Suche

CVE-2026-81027

one-api

Beschreibung

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and otherwise rejects the caller, while the path-parameter branch sets the selected-channel value from c.Param(-channelid-) with no role check at all. The route carrying that parameter sits behind token authentication only, so any account holding a valid API token reaches it. The value flows to the distributor, which loads the channel by integer identifier with no scoping to the caller-s user or group, and then sets the outbound Authorization header to that channel-s stored key and directs the request at the channel-s base URL. A low-privilege account can therefore pin any channel by incrementing an identifier, causing the server to make upstream requests bearing an operator-configured provider key the account was never granted, and bypassing both the per-group restriction and the channel-s model allowlist.

CVSS 8.5EPSS 0.28600000000000003%Risiko 0.87
Quelle öffnen
Veröffentlicht
2026-08-26 16:16:45
Betroffene Versionen
unknown
Typ
Webanwendung
Zuletzt geändert
2026-08-26 18:17:05
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N